2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3374 | CRITICAL | 9.9 | 1.9% | Jul 31, 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem... |
| CVE-2020-16165 | CRITICAL | 9.8 | 1.2% | Jul 30, 2020 | The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to t... |
| CVE-2020-16163 | CRITICAL | 9.1 | 1.3% | Jul 30, 2020 | An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lac... |
| CVE-2020-14158 | CRITICAL | 9.1 | 1.8% | Jul 30, 2020 | The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity ... |
| CVE-2020-3699 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Possible out of bound access while processing assoc response from host due to improper length check before copying into ... |
| CVE-2020-3698 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response f... |
| CVE-2020-3688 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapd... |
| CVE-2020-3671 | CRITICAL | 9.8 | 0.9% | Jul 30, 2020 | Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compu... |
| CVE-2020-7699 | CRITICAL | 9.8 | 4.7% | Jul 30, 2020 | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP r... |
| CVE-2020-14316 | CRITICAL | 9.9 | 1.6% | Jul 29, 2020 | A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's... |
| CVE-2020-15588 | CRITICAL | 9.8 | 12.7% | Jul 29, 2020 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled serve... |
| CVE-2020-15086 | CRITICAL | 9.8 | 2.7% | Jul 29, 2020 | In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered ... |
| CVE-2020-4567 | CRITICAL | 9.8 | 2.3% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote atta... |
| CVE-2020-2076 | CRITICAL | 9.8 | 1.3% | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by direct... |
| CVE-2020-14487 | CRITICAL | 9.8 | 2.2% | Jul 29, 2020 | OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly ... |
| CVE-2020-9691 | CRITICAL | 9.6 | 6.0% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Suc... |
| CVE-2020-7698 | CRITICAL | 9.8 | 1.7% | Jul 29, 2020 | This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endp... |
| CVE-2020-7697 | CRITICAL | 9.8 | 2.0% | Jul 29, 2020 | This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affec... |
| CVE-2020-5377 | CRITICAL | 9.1 | 48.3% | Jul 28, 2020 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. ... |
| CVE-2020-15623 | CRITICAL | 9.8 | 8.3% | Jul 28, 2020 | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e1... |
| CVE-2020-15615 | CRITICAL | 9.8 | 8.1% | Jul 28, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e... |
| CVE-2020-15614 | CRITICAL | 9.8 | 8.1% | Jul 28, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e... |
| CVE-2020-15613 | CRITICAL | 9.8 | 8.1% | Jul 28, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e... |
| CVE-2020-15612 | CRITICAL | 9.8 | 8.4% | Jul 28, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e... |
| CVE-2020-15611 | CRITICAL | 9.8 | 8.3% | Jul 28, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now